CISM Certified Information Security Manager – Question1365

Detailed business continuity plans should be based PRIMARILY on:

A.
consideration of different alternatives.
B. the solution that is least expensive.
C. strategies that cover all applications.
D. strategies validated by senior management.

Correct Answer: D

Explanation:

Explanation:
A recovery strategy identifies the best way to recover a system in ease of disaster and provides guidance based on detailed recovery procedures that can be developed. Different strategies should be developed and all alternatives presented to senior management. Senior management should select the most appropriate strategy from the alternatives provided. The selected strategy should be used for further development of the detailed business continuity plan. The selection of strategy depends on criticality of the business process and applications supporting the processes. It need not necessarily cover all applications. All recovery strategies have associated costs, which include costs of preparing for disruptions and putting them to use in the event of a disruption. The latter can be insured against, but not the former. The best recovery option need not be the least expensive.